U.S. prosecutors and courts advanced multiple cases tied to large-scale cryptocurrency fraud and laundering operations that targeted American victims through fake trading platforms and social-engineering lures. In one California case, Jingliang Su, a Chinese national, was sentenced to 46 months in prison after admitting he helped launder more than $36.9 million stolen from 174 victims by a scam network operating from Cambodia; the court also ordered more than $26.8 million in restitution. Authorities said the fraud used unsolicited messages, calls, texts, dating platforms, and bogus crypto-investment websites to persuade victims to transfer funds, which were then routed through U.S. shell companies, bank accounts, Deltec Bank in the Bahamas, and Tether (USDT) wallets controlled abroad.
In a related prosecution, Daren Li, a dual citizen of China and St. Kitts and Nevis, pleaded guilty to conspiracy to commit money laundering after authorities said he and co-conspirators moved more than $73 million in victim proceeds through shell companies, U.S. financial accounts, wire transfers, and conversion into USDT; he was later sentenced to 20 years in federal prison. The cases form part of a broader Justice Department crackdown on transnational crypto-enabled investment scams and money-laundering networks, with officials reporting that multiple co-conspirators have pleaded guilty and that the U.S. Secret Service played a central investigative role.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
In February 2026, Daren Li was sentenced to 20 years in federal prison for his role in a multimillion-dollar cryptocurrency scam and related laundering activity targeting U.S. victims.
In January 2026, a federal court in Los Angeles sentenced Jingliang Su to 46 months in prison and ordered $26,867,242 in restitution for his role in laundering proceeds from a Cambodia-based digital asset investment fraud operation.
In June 2025, Jingliang Su pleaded guilty to conspiracy to operate an illegal money transmitting business for laundering proceeds from a digital asset investment fraud scheme that stole more than $36.9 million from 174 U.S. victims.
In November 2024, Daren Li pleaded guilty to conspiracy to commit money laundering for helping launder more than $73 million from cryptocurrency investment scam victims through shell companies, U.S. bank accounts, wire transfers, and Tether conversions.
Daren Li, a dual citizen of China and St. Kitts and Nevis, was arrested at Hartsfield-Jackson Atlanta International Airport for his alleged role in laundering proceeds from cryptocurrency investment scams and was transferred to the Central District of California.
After his September 2019 arrest, Nashatka was arraigned in San Francisco federal court on hacking-related charges tied to the alleged $1.4 million cryptocurrency theft scheme and released on bond.
Nashatka was arrested in New York in connection with the 2017 cryptocurrency exchange theft scheme before being brought to federal court in the Bay Area.
On December 26, 2017, the same alleged cryptocurrency theft scheme was used to steal an additional approximately $800,000 from one victim.
Between December 20 and 21, 2017, the alleged exchange takeover scheme stole roughly $600,000 in cryptocurrency from hundreds of victims whose credentials were captured through the spoofed site.
In December 2017, Anthony Tyler Nashatka and Elliott Gunton allegedly used a victim's identity to gain control of a cryptocurrency exchange's domain settings, disabled the company's servers, and redirected users to a fake website to harvest wallet addresses and private keys.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourcejustice.gov
Open sourcecybersecuritynews.com
Open sourcejustice.gov
Open sourcejustice.gov
Open sourcecbsnews.com
Open sourcestorage.courtlistener.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.